2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7611MEDIUM5.4The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2024-7599MEDIUM5.4The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ para...
CVE-2024-44837MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component \bean\Manager.java of Drug v1.0 allows attackers to execute ...
CVE-2024-45405MEDIUM6`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their con...
CVE-2024-45300MEDIUM5.9alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio...
CVE-2024-45299MEDIUM6.5alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio...
CVE-2024-45040MEDIUM5.9gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments t...
CVE-2024-45039MEDIUM6.2gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundn...
CVE-2024-8427MEDIUM4.3The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unau...
CVE-2024-8317MEDIUM5.4The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ad...
CVE-2024-45751MEDIUM5.9tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed ...
CVE-2024-7415MEDIUM5.3The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including...
CVE-2024-40865MEDIUM5.3The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. ...
CVE-2024-44082MEDIUM4.3In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, i...
CVE-2024-45400MEDIUM6.1ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possib...
CVE-2024-39278MEDIUM4.6Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow...
CVE-2024-45157MEDIUM5.1An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used...
CVE-2024-42491MEDIUM5.7Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and ...
CVE-2024-45392MEDIUM4.3SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficien...
CVE-2024-44728MEDIUM6.1Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, ...
CVE-2024-45589MEDIUM5.9RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts an...
CVE-2024-45176MEDIUM6.1An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web ...
CVE-2024-45096MEDIUM6.5IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information thro...
CVE-2024-8445MEDIUM5.7The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authen...
CVE-2024-8473MEDIUM6.1Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now